From: Dan Carpenter Date: Fri, 25 Aug 2017 10:36:57 +0000 (+0300) Subject: scsi: qedi: off by one in qedi_get_cmd_from_tid() X-Git-Tag: v4.13.4~45 X-Git-Url: https://www.infradead.org/git/?a=commitdiff_plain;h=9e071695a5be9ca758cc5c1d1b92ee98c4e8df1a;p=users%2Fdwmw2%2Flinux.git scsi: qedi: off by one in qedi_get_cmd_from_tid() commit fa2d9d6e894e096678a50ef0f65f7a8c3d8a40b8 upstream. The > here should be >= or we end up reading one element beyond the end of the qedi->itt_map[] array. The qedi->itt_map[] array is allocated in qedi_alloc_itt(). Fixes: ace7f46ba5fd ("scsi: qedi: Add QLogic FastLinQ offload iSCSI driver framework.") Signed-off-by: Dan Carpenter Acked-by: Manish Rangankar Signed-off-by: Martin K. Petersen Signed-off-by: Greg Kroah-Hartman --- diff --git a/drivers/scsi/qedi/qedi_main.c b/drivers/scsi/qedi/qedi_main.c index 2c37836848152..85e7bae4a7ef8 100644 --- a/drivers/scsi/qedi/qedi_main.c +++ b/drivers/scsi/qedi/qedi_main.c @@ -1575,7 +1575,7 @@ struct qedi_cmd *qedi_get_cmd_from_tid(struct qedi_ctx *qedi, u32 tid) { struct qedi_cmd *cmd = NULL; - if (tid > MAX_ISCSI_TASK_ENTRIES) + if (tid >= MAX_ISCSI_TASK_ENTRIES) return NULL; cmd = qedi->itt_map[tid].p_cmd;